Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
References
Link | Resource |
---|---|
https://github.com/BastilleResearch/mousejack/blob/master/doc/advisories/bastille-2.logitech.public.txt | Third Party Advisory |
https://www.kb.cert.org/vuls/id/981271 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Information
Published : 2019-06-29 13:15
Updated : 2019-07-08 07:47
NVD link : CVE-2016-10761
Mitre link : CVE-2016-10761
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
logitech
- unifying_receiver_firmware
- k750_firmware
- k400r
- k360_firmware
- k360
- k750
- k830_firmware
- k830
- unifying_receiver
- k400r_firmware